Government of the Republic of Trinidad and Tobago
gov.tt

Securing the Nation's Digital Infrastructure

TTCSIRT-406.30.09.22: Critical Microsoft Exchange 0-Day Vulnerability Actively Exploited

Critical Microsoft Exchange 0-Day Vulnerability Actively Exploited Description The two vulnerabilities for on-premise Microsoft Exchange have been discovered and are now being tracked as a Server-Side Request Forgery vulnerability, CVE-2022-41040, and a remote code execution vulnerability, CVE-2022-41082. The two vulnerabilities are being exploited together to remotely trigger arbitrary code execution which essentially allows threat actors …

TT-CSIRT-405.25.07.22: SonicWall Security Vulnerabilities

SonicWall has released security updates to address vulnerabilities in SonicWall Global Management System (GMS) and SonicWall Analytics On-Prem . Exploitation of these vulnerabilities could allow for an attacker to gain unauthorized access to an affected system. TT-CSIRT strongly encourages administrators to review the following releases from SonicWall and apply the necessary updates immediately: SonicWall Global …

TT-CSIRT-404.27.06.22: Cisco Email Security Vulnerabilities

Cisco has released security updates to address vulnerabilities in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager. Exploitation of this vulnerability could allow for an unauthenticated attacker to gain unauthorized access to the web-based management interface of the affected device. TT-CSIRT strongly encourages administrators to review the following releases from Cisco …

TT-CSIRT-403.01.06.22: Workaround Guidance for MSDT Vulnerability

Microsoft has released workaround guidance to address a remote code execution (RCE) vulnerability—CVE-2022-30190, known as “Follina”—affecting the Microsoft Support Diagnostic Tool (MSDT) in Windows. This vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the …

Ransomware Joint Advisory

This is a joint cyber security advisory from the Trinidad and Tobago Cyber Security Incident Response Team (TT-CSIRT), Trinidad and Tobago Police Service Cyber and Social Media Unit (TTPS CSMU) and the National Information and Communication Technology Company Limited (iGovTT). This advisory serves to warn all entities within Trinidad and Tobago about increased ransomware attacks …

Ransomware Response Checklist

The following information is taken from the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Should your organization be a victim of ransomware, TT-CSIRT strongly recommends responding by using the following checklist. Be sure to move through the first three steps in sequence. Detection and Analysis Determine which systems were impacted, and immediately isolate them. If …

Ransomware Prevention

The following information is taken from the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Be Prepared Refer to the best practices and references below to help manage the risk posed by ransomware and support your organization’s coordinated and efficient response to a ransomware incident. Apply these practices to the greatest extent possible based on availability …

Increased Cyber Activity in Trinidad and Tobago and the Region

The Trinidad and Tobago Cyber Security Incident Response Team (TT-CSIRT) has observed a sharp increase in malicious cyber activity targeting local and regional entities over the past two (2) months. The TT-CSIRT is urging all entities (public and private) to adopt a heightened state of awareness and be guided by the following: Top Threats to …

TT-CSIRT-402.13.04.22: Microsoft Security Updates April 2022

Microsoft has released updates to address multiple vulnerabilities in Microsoft software. An attacker can exploit some of these vulnerabilities to take control of an affected system. The list of updates addresses several critical vulnerabilities, one of which is being actively exploited in the wild by threat actors. The TT-CSIRT strongly encourages users and administrators to …

TT-CSIRT-401.11.04.22: FortiClient Vulnerabilities

Fortinet has released security updates to address multiple vulnerabilities in FortiClient for Windows and Linux. An attacker could exploit some of these vulnerabilities to take control of an affected system or access sensitive information. TT-CSIRT encourages users/administrators to review the following releases from Fortinet and apply the necessary updates: FortiClient (Windows) – Privilege Escalation FortiClient …